XML 66 R34.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]

The Corporation has invested in accepted technologies, and continually reviews processes and practices that are designed to protect our networks, computers and data from damage or unauthorized access, and maintains an information security risk insurance policy. On an on-going basis the Corporation assesses its cyber security procedures and controls and performs network penetration tests on at least an annual basis. All employees receive monthly information security awareness training.

The Corporation’s cybersecurity risk management program is designed to assess, identify, and manage material risks from cybersecurity threats and is an integral part of the overall risk management program. Cybersecurity risk includes exposure to failures or interruptions of service or security breaches resulting from malicious technological attacks that impact the confidentiality, integrity, or availability of our or third parties’ operations, systems, or data. The Corporation assesses its cyber security procedures and controls on an on-going basis as safeguarding its systems and data is critical to its operations and business strategy.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] The Corporation’s cybersecurity risk management program is designed to assess, identify, and manage material risks from cybersecurity threats and is an integral part of the overall risk management program. Cybersecurity risk includes exposure to failures or interruptions of service or security breaches resulting from malicious technological attacks that impact the confidentiality, integrity, or availability of our or third parties’ operations, systems, or data. The Corporation assesses its cyber security procedures and controls on an on-going basis as safeguarding its systems and data is critical to its operations and business strategy.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block] The Board of Directors provides oversight of the risk management program and setting the Corporation’s cyber risk profile, which includes risks from cybersecurity threats, enterprise cyber strategy, and key cyber initiatives. The Board has appointed a Risk Management Committee currently made up of six members of the Board with governance and oversight of the Corporation’s enterprise-wide risk management program. The members of the Risk Management Committee collectively have years of business management and professional experience in the banking industry and other industries including exposure to cyber risk management considerations. The Board also meets with our internal and external auditors, and federal and state regulators to review and discuss reports on risk, examination, and regulatory compliance matters. In fulfilling its role, the Risk Management Committee is actively engaged with management regarding cyber security procedures and controls to manage and mitigate cybersecurity-related risks. Management provides at least quarterly information security reports to the Risk Management Committee who provides a report to the Board of its discussions and decisions. These reports to the Risk Management Committee address management’s efforts to monitor, detect and prevent cyber threats. In addition, the Board of Directors is engaged, as needed, in accordance with the Incident Response Plan.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Risk Management Committee
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The members of the Risk Management Committee collectively have years of business management and professional experience in the banking industry and other industries including exposure to cyber risk management considerations. The Board also meets with our internal and external auditors, and federal and state regulators to review and discuss reports on risk, examination, and regulatory compliance matters. In fulfilling its role, the Risk Management Committee is actively engaged with management regarding cyber security procedures and controls to manage and mitigate cybersecurity-related risks. Management provides at least quarterly information security reports to the Risk Management Committee who provides a report to the Board of its discussions and decisions. These reports to the Risk Management Committee address management’s efforts to monitor, detect and prevent cyber threats. In addition, the Board of Directors is engaged, as needed, in accordance with the Incident Response Plan.
Cybersecurity Risk Role of Management [Text Block] The Corporation has an information security program that is primarily managed by the Information Security Department, which is led by the Chief Risk Management Officer and the Director of Information Security and supported by the Information Technology Operations Department, which is led by the Chief Information Officer. The Information Security Department is led by the Director of Information Security, and is responsible for day-to-day management of the information security program including system monitoring, vulnerability scans, employee security training including phishing exercises, security controls, and building strong relationships with security vendors. The Chief Risk Management Officer, the Chief Information Officer, the Director of Information Security and the other members of the Information Security Department are qualified by years of experience, post-secondary education, industry certifications and regular continuing education. A network penetration test and vulnerability assessment are performed at a minimum annually by a third-party vendor. The Information Security Committee is the management committee responsible for the oversight of the Information Security Program and is also responsible for policy development and information security risk assessment. This committee meets at least quarterly to discuss and review the information security program. The Information Security Program is updated at least annually and the Board of Directors, with input from the Risk Management Committee, approves all material changes.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] Chief Risk Management Officer and the Director of Information Security
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] The Chief Risk Management Officer, the Chief Information Officer, the Director of Information Security and the other members of the Information Security Department are qualified by years of experience, post-secondary education, industry certifications and regular continuing education. A network penetration test and vulnerability assessment are performed at a minimum annually by a third-party vendor. The Information Security Committee is the management committee responsible for the oversight of the Information Security Program and is also responsible for policy development and information security risk assessment. This committee meets at least quarterly to discuss and review the information security program. The Information Security Program is updated at least annually and the Board of Directors, with input from the Risk Management Committee, approves all material changes.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The Corporation has an Incident Response Plan that provides a documented guideline for handling potential threats and taking appropriate measures including timely notification and escalation to executive leadership and the Board of Directors. The Incident Response Plan is managed by the Incident Response Team which includes the Director of Information Security, Chief Risk Management Officer, Chief Information Officer, and other essential members of management. The Incident Response Plan is reviewed and tested at least annually
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true